PT-2007-4228 · Isc+2 · Isc Bind+2
Amit Klein
·
Publicado
2007-09-11
·
Atualizado
2018-10-16
·
CVE-2007-2930
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
ISC BIND 8 versions prior to 8.4.7-P1
Description
The issue affects the NSID SHUFFLE ONLY and NSID USE POOL PRNG algorithms, which generate predictable DNS query identifiers when sending outgoing queries, such as NOTIFY messages, when answering questions as a resolver. This allows remote attackers to poison DNS caches via unknown vectors.
Recommendations
For versions prior to 8.4.7-P1, update to version 8.4.7-P1 or later to resolve the issue.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Bind Server
Hp-Ux
Isc Bind